Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware post, september 23, 2024 A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools. “They used advanced techniques like GeoServer exploitation, spear-phishing, and customized malware (Cobalt Strike and EAGLEDOOR) to infiltrate and exfiltrate data. The use of public cloud services for hosting malicious files and the multi-protocol support of EAGLEDOOR highlight the complexity and adaptability of their operations.” Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware (thehackernews.com): Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware geopolitics malware 2024China